Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed <embed>), which can be chained to execute JavaScript whenever users view impacted content (e.g., announcements). This can result in admin account takeover. This issue has been patched in version 1.4.0.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/Mmo-kali/CVE/blob/main/CVE-2025-59525/2025-08-Horilla_Vulnerability_2.pdf | Exploit Third Party Advisory | 
| https://github.com/horilla-opensource/horilla/releases/tag/1.4.0 | Release Notes | 
| https://github.com/horilla-opensource/horilla/security/advisories/GHSA-rp5m-vpqr-vpvp | Vendor Advisory Exploit | 
Configurations
                    History
                    29 Sep 2025, 14:04
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Horilla Horilla horilla | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 6.1 | 
| CPE | cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:* | |
| References | () https://github.com/Mmo-kali/CVE/blob/main/CVE-2025-59525/2025-08-Horilla_Vulnerability_2.pdf - Exploit, Third Party Advisory | |
| References | () https://github.com/horilla-opensource/horilla/releases/tag/1.4.0 - Release Notes | |
| References | () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-rp5m-vpqr-vpvp - Vendor Advisory, Exploit | 
24 Sep 2025, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-09-24 19:15
Updated : 2025-09-29 14:04
NVD link : CVE-2025-59525
Mitre link : CVE-2025-59525
CVE.ORG link : CVE-2025-59525
JSON object : View
Products Affected
                horilla
- horilla
